No more typing reviews! Try our Samantha, our new voice AI agent.

NetWitness Platform vs Sentinel comparison

Why PeerSpot?
 

Comparison Buyer's Guide

Executive SummaryUpdated on Jun 3, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

NetWitness Platform
Ranking in Security Information and Event Management (SIEM)
35th
Average Rating
7.4
Reviews Sentiment
7.4
Number of Reviews
36
Ranking in other categories
Log Management (36th)
Sentinel
Ranking in Security Information and Event Management (SIEM)
14th
Average Rating
7.6
Reviews Sentiment
6.8
Number of Reviews
18
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of October 2026, in the Security Information and Event Management (SIEM) category, the mindshare of NetWitness Platform is 1.2%, up from 0.7% compared to the previous year. The mindshare of Sentinel is 2.7%, down from 4.1% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Security Information and Event Management (SIEM) Mindshare Distribution
ProductMindshare (%)
Sentinel2.7%
NetWitness Platform1.2%
Other96.1%
Security Information and Event Management (SIEM)
 

Featured Reviews

reviewer1130436 - PeerSpot reviewer
Information Technology Security and Infrastructure Expert at a government with 201-500 employees
Helps to deal with potential attacks and is available at a reasonable price
My company has had many benefits from the use of the product in the last eight years. The tool has streamlined our company's incident response process since it serves as a log repository, which allows us to correlate events and access different technology stacks. In our company, we were able to actually find some potential attacks, so it has been very helpful. The tool's integration capability isn't so great. In my company, we managed to integrate it with our Microsoft Azure Subscription, after which we managed to integrate it with other tools. You will face a lot of difficulties if you want to integrate it with your database monitoring tool, PAM solutions, or IAM products. The product has done well overall for my company's teams to deal with their workflow efficiency. I would not recommend the product to others. I rate the tool a seven out of ten.
PT
Senior Specialist at a tech vendor with 10,001+ employees
Improved incident monitoring has reduced false positives and supports audit-ready reporting
The best features Sentinel offers, in my experience, include the filtering features and the ability to run KQL queries so that I can understand what table has what and when the last log has been monitored and reported. Sentinel has positively impacted my organization by improving monitoring significantly. As a pay-as-you-go service, we are ingesting logs as needed. When the pay-as-you-go service is enabled, we can either ingest whenever there is a spike in the logs, and when there are fewer logs, we can reduce the ingestion. This approach is helpful for both the organization and me. In terms of metrics showing how Sentinel has helped, as part of log filtering, we have reduced around thirty to thirty-five percent of false-positive incident creation. We have also cleared some audits by enabling log retention in Sentinel, allowing us to pull out data for audits when necessary using both hot retention and cold retention. This has helped the organization as a whole.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Over time, NetWitness Logs and Packets has matured from a boxed solution with multiple parts to the current, more streamlined version for which we only need the software license to put it up on our own cloud and deliver it to multiple clients."
"It gives the ability to investigate into network traffic in the Net and the organization what we couldn't do before."
"The most valuable features are the packet decoder, log decoder, and concentrator."
"The most valuable feature is the security that it provides."
"Once it is deployed and you are used to it, you can do whatever you want."
"Thanks to this tool, we have a small SOC running in our company."
"The detection of ransomware in the internal network has benefited my organization."
"Incident management is its most valuable feature."
"The most valuable feature of this solution is that it provides a central locking system for many event sources."
"The native integration with out-of-the box format is hassle free and allows data to be used advantageously."
"It makes everything easier by automating some tasks and growing with our needs."
"Sentinel has positively impacted my organization by improving monitoring significantly."
"If Sentinel is integrated with Identity Manager and User Application Portal, the solution runs simply perfect!"
"The tool is simple to use."
"Sentinel gave us logs to tell us what's going right and wrong in your environment so we could secure the network."
"The most valuable feature is the flexible log for identifying security threats inside an application. Sentinel is very good at this."
 

Cons

"There is no support for this product in this country, so problems have to be resolved through global technical teams."
"The solution should have more integration capabilities with different platforms."
"The multi-tenant capabilities are lagging compared to IBM QRadar."
"The product's licensing models are complex to understand. This particular area needs improvement."
"It should have a monitoring feature. It would help us analyze the current state of attacks faster from a single platform."
"We have encountered issues with unresolved crashes."
"It is overly complicated. It has taken years to implement and the return on investment just isn't there."
"I believe that integrating the solution with other products such as Oracle would be beneficial."
"I rate Sentinel a six out of ten for scalability."
"You need a lot of Unix scripting knowledge in order to manage the tool, which is one of the main issues that we faced."
"Documentation for security aspects could be improved. It is difficult to find clear information about encryption or risks that are addressed."
"Price is always a consideration, so the price would be nice if it were lower."
"I would like to see a better reporting work structure on the dashboard."
"Creating a drag-and-drop dashboard or workbook in Sentinel is a little more complex compared to other tools like LogRhythm and IBM QRadar."
"It is an ancient product."
"The dashboard and customer view should be improved."
 

Pricing and Cost Advice

"The product is expensive."
"It’s cheaper to run virtual machines in a VMware environment."
"The NetWitness Platform may be affordable only for enterprise-level customers, as it may not be within the budget of small and medium-sized businesses."
"It is cheap."
"This is a pricey solution; it's not cheap."
"We have a perpetual license, so the total cost of ownership is not very expensive. It's a good investment."
"The product price was reasonable for my region and the market."
"The new pricing and licensing mechanisms are fair. I would advise always to get the full solution (i.e., not only Logs)."
"Sentinel is moderately priced."
"The solution’s pricing is aligned with its competitors."
"We receive a pricing discount because of our ongoing partnership with Micro Focus."
"Sentinel is a subscription-based solution."
"We inquired about getting support from the vendor, Micro Focus, but the cost was very high."
"Sentinel's slightly on the expensive side."
report
Use our free recommendation engine to learn which Security Information and Event Management (SIEM) solutions are best for your needs.
915,341 professionals have used our research since 2012.
 

Comparison Review

VS
Manager, Enterprise Risk Consulting at a tech company with 1,001-5,000 employees
Feb 26, 2015
HP ArcSight vs. IBM QRadar vs. ​McAfee Nitro vs. Splunk vs. RSA Security vs. LogRhythm
We at Infosecnirvana.com have done several posts on SIEM. After the Dummies Guide on SIEM, we are following it up with a SIEM Product Comparison – 101 deck. So, here it is for your viewing pleasure. Let me know what you think by posting your comments below. The key products compared here are…
 

Top Industries

By visitors reading reviews
Construction Company
12%
Financial Services Firm
11%
Comms Service Provider
10%
Outsourcing Company
10%
Outsourcing Company
10%
Financial Services Firm
9%
Manufacturing Company
9%
Comms Service Provider
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business8
Midsize Enterprise7
Large Enterprise20
By reviewers
Company SizeCount
Small Business9
Midsize Enterprise3
Large Enterprise8
 

Questions from the Community

What is your experience regarding pricing and costs for NetWitness Platform?
The pricing is comparable to others, and I consider the cost to be intermediate. Specific cost details are unknown to me.
What needs improvement with NetWitness Platform?
There is currently no need for improvement in the SIEM ( /categories/security-information-and-event-management-siem ), though there could be potential enhancements by integrating with AI.
What is your primary use case for NetWitness Platform?
I use NetWitness Platform ( /products/netwitness-platform-reviews ) in the financial industry as a good product with excellent capabilities and integration with various devices.
What is your experience regarding pricing and costs for NetIQ Sentinel?
My experience with pricing, setup cost, and licensing shows that while it is a little on the higher side, since it is part of a package for all Microsoft products, I feel it is a better choice comp...
What needs improvement with NetIQ Sentinel?
Sentinel needs minimal improvement, though improvements are ongoing. Everything seems to be functioning perfectly, and I don't have any specific inputs for improvements I would like to see in Senti...
What is your primary use case for NetIQ Sentinel?
My main use case for Sentinel is that I'm a subject matter expert for Sentinel, specifically for security incident event and event management. I head the SME for SIEM in LTIMindtree for this curren...
 

Also Known As

RSA Security Analytics
NetIQ Sentinel, Novell SIEM
 

Overview

 

Sample Customers

Los Angeles World Airports, Reply
Faysal Bank, GaVI, Handelsbanken, ISC Mªnster, Lambeth Council, Swisscard, The Municipality of Siena, Tukes, University of Dayton, University of the Sunshine Coast
Find out what your peers are saying about NetWitness Platform vs. Sentinel and other solutions. Updated: September 2026.
915,341 professionals have used our research since 2012.